Ferruna App Privacy Policy
Last updated 20/07/2026 · Policy version 2026-07.1 · Looking for the website privacy policy?
Ferruna is an iron-supplement tracker developed by Biswanath Dutta in Sydney, Australia. This policy explains what data the app collects, how we use it, who we share it with, and the rights you have under the Australian Privacy Act 1988 (as amended by the Privacy Act Review reforms, current April 2026) and equivalent overseas laws where applicable.
What we collect on your device
- Supplement logs (dose, date, whether taken)
- Reminder and schedule preferences
- Optional: blood test results and ferritin targets you choose to record
- Consent choices and timestamps (so we can show you an audit trail and so we know which features you permitted)
All of the above is stored locally on your iPhone using Apple's SwiftData framework. Ferruna does not operate servers that store this information.
What we read from HealthKit (only if you grant HealthKit consent)
- Dietary iron entries from Apple Health (to reconcile what you logged in Ferruna with what Apple Health already knows)
- For iron entries written by other apps, we also record which app wrote them (its name and app identifier). These entries are held on your device in a review queue and count toward your streaks and insights only after you approve them. The source-app details are kept for up to 90 days after you review an entry (for auditing and to avoid duplicate imports), then removed automatically. You can delete the whole queue at any time with Reset All Data in Settings.
What we write to HealthKit (only if you grant HealthKit consent)
- A dietary iron sample each time you log a dose in Ferruna, tagged so we can distinguish our entries from other apps
HealthKit data never leaves your device through Ferruna. We do not sync it to any server we control.
Watch companion (if you install Ferruna on Apple Watch)
A minimal summary of your current day — supplement name, dosage, today's taken/not-taken status, current streak length, and (if you've entered one) your most recent ferritin value — is transferred from the iPhone to the Watch via Apple's Watch Connectivity framework. The Watch is a paired accessory to your iPhone; the transfer happens over the encrypted Bluetooth / Wi-Fi link Apple provides between your own devices. No data is sent to any server through this channel. A copy of your current consent choices is mirrored into the Ferruna App Group so the widget and Watch companion can honour them without re-reading the database.
What we send to Google (only if you grant AI Coach / Gemini consent)
When you use AI Coach or Ferritin Trends, a text prompt summarising your recent adherence, streak length, supplement type and dose, ferritin readings you have entered, target levels (numeric values only — never the names you give them), absorption factors, reminder time, and any questions you type is sent to Google's Gemini API over HTTPS to generate a response. Google may process this data on servers located outside Australia; by granting AI Coach consent you agree to this overseas disclosure. This prompt never contains your name, email, Apple ID, device identifiers, or raw HealthKit samples. Google's handling of this data is governed by the Google API Services Terms of Service and Gemini API Additional Terms.
What we collect for advertising (Free tier only, and only if you allow tracking when iOS asks)
Ads are served via Google AdMob. Permission to use your advertising identifier is requested by iOS itself through the App Tracking Transparency prompt — never by an in-app switch. If you allow tracking, an anonymous advertising identifier (IDFA) and device-level signals may be shared with AdMob for ad selection; if you decline, ads are non-personalised (device signals such as IP address and device model still reach Google for ad serving, frequency capping, and fraud prevention, but not your advertising identifier). You can change your choice at any time in iOS Settings → Privacy & Security → Tracking. Your supplement logs, iron levels, HealthKit samples, and chat messages are never shared with advertisers. Ferruna Premium subscribers see no ads and no ad SDK is initialised.
What we don't collect
- No name, email, or account — Ferruna has no account system
- No precise location, photos, contacts, or camera access
- No third-party analytics (no Firebase, Mixpanel, Amplitude, or similar)
- No crash-report SDKs that could include personal data
Your rights under the Australian Privacy Act
- Access: you can see everything Ferruna stores about you from inside the app (Today, Streaks, Progress, Settings → Privacy & Data)
- Correction: you can edit or delete any log, blood test, or target at any time
- Deletion: you can delete any individual log, blood test, or target at any time, or wipe everything at once with Settings → Data → Reset All Data (deletes all supplement logs, blood tests, trend results, and imported Health records from this device); uninstalling the app also removes everything stored on-device.
- Consent withdrawal: Settings → Privacy & Data lets you revoke any consent and see recent changes (the most recent 25 entries)
- Complaint: if you are unhappy with how we handle your data, contact us first (email below), or escalate to the Office of the Australian Information Commissioner (oaic.gov.au)
Storage location
Data stays on your device. If iCloud Backup is enabled for Ferruna on your iPhone, your SwiftData database may be included in encrypted device backups managed by Apple under Apple's privacy terms. Ferruna itself does not manage iCloud backup content.
Children
Ferruna is not directed at children under 16 and should not be used without parental supervision by anyone under 18. We do not knowingly collect data from children.
Changes to this policy
If this policy changes materially, the app will prompt you to re-review your consent choices on next launch. Policy version strings (like 2026-07 above) let you see exactly which version you last acknowledged.
Contact
Biswanath Dutta — hello@ferruna.com.au
← Back to Ferruna